jafoca's starred repositories

byob

An open-source post-exploitation framework for students, researchers and developers.

Language:PythonLicense:GPL-3.0Stargazers:8847Issues:325Issues:502

monkey

Infection Monkey - An open-source adversary emulation platform

Language:PythonLicense:GPL-3.0Stargazers:6575Issues:241Issues:1518

ScoutSuite

Multi-Cloud Security Auditing Tool

Language:PythonLicense:GPL-2.0Stargazers:6364Issues:129Issues:862

awesome-shodan-queries

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

AD-Attack-Defense

Attack and defend active directory using modern post exploitation adversary tradecraft activity

fuxploider

File upload vulnerability scanner and exploitation tool.

Language:PythonLicense:GPL-3.0Stargazers:3000Issues:68Issues:0

OSCPRepo

A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.

APTSimulator

A toolset to make a system look as if it was the victim of an APT attack

Language:BatchfileLicense:MITStargazers:2416Issues:120Issues:9

fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Language:PythonLicense:GPL-3.0Stargazers:1840Issues:31Issues:35

Shuffle

Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.

Language:ShellLicense:AGPL-3.0Stargazers:1584Issues:39Issues:1005

SprayingToolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

Language:PythonLicense:GPL-3.0Stargazers:1437Issues:35Issues:17

flightsim

A utility to safely generate malicious network traffic patterns and evaluate controls.

Language:GoLicense:NOASSERTIONStargazers:1220Issues:35Issues:50

awslambdaproxy

An AWS Lambda powered HTTP/SOCKS web proxy

Language:GoLicense:MITStargazers:764Issues:21Issues:20

WitnessMe

Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

Language:PythonLicense:GPL-3.0Stargazers:722Issues:22Issues:33

Spray

A Password Spraying tool for Active Directory Credentials by Jacob Wilkin(Greenwolf)

Language:ShellLicense:GPL-3.0Stargazers:709Issues:36Issues:7

lme

Logging Made Easy

Language:ShellLicense:Apache-2.0Stargazers:708Issues:46Issues:113

SSRF_Vulnerable_Lab

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

Language:PHPLicense:MITStargazers:660Issues:19Issues:5

0xsp-Mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and techniques of an advanced adversary in a network.

Language:PascalLicense:GPL-3.0Stargazers:531Issues:28Issues:6

PentestHardware

Kinda useful notes collated together publicly

stoq

An open source framework for enterprise level automated analysis.

Language:PythonLicense:Apache-2.0Stargazers:396Issues:41Issues:70

celerystalk

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

Language:PythonLicense:MITStargazers:396Issues:25Issues:82

cotopaxi

Set of tools for security testing of Internet of Things devices using specific network IoT protocols

Language:PythonLicense:GPL-2.0Stargazers:349Issues:15Issues:4

GatherContacts

A Burp Suite Extension to pull Employee Names from Google and Bing LinkedIn Search Results

Language:JavaStargazers:180Issues:7Issues:0

yabin

A Yara rule generator for finding related samples and hunting

Language:PythonLicense:Apache-2.0Stargazers:151Issues:20Issues:2

crawler

Go process used to crawl websites

Language:GoLicense:GPL-3.0Stargazers:150Issues:8Issues:9

static-files

A collection of static files maintained by the Sublime team, primarily used for phishing defense.

Hornets-Nest

Purple Team Security

k8s

Kubernetes configuration file to boostrap trandoshan cluster

lambda-webbugs

A proof of concept for delivering webbugs via AWS lambda

Language:PythonStargazers:43Issues:3Issues:0

gsvmind

Random generator of GSV names, in honor to "The Culture" series by Ian M. Banks!

Language:PythonLicense:GPL-3.0Stargazers:4Issues:2Issues:0